First published: Fri Mar 12 2021(Updated: )
Adobe Framemaker version 2020.0.1 (and earlier) is affected by an Out-of-bounds Read vulnerability when parsing a specially crafted file. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Framemaker | ||
Adobe Framemaker | <2020.0.2 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21056 is a vulnerability that allows remote attackers to execute arbitrary code on Adobe FrameMaker.
An attacker can exploit CVE-2021-21056 by tricking the target into visiting a malicious page or opening a malicious PDF file.
CVE-2021-21056 has a severity rating of critical with a CVSS score of 7.8.
Adobe FrameMaker versions up to and including 2020.0.2 are affected by CVE-2021-21056.
To fix CVE-2021-21056, users should update Adobe FrameMaker to a version that is not affected by the vulnerability.